# Using Graylog as a SIEM

**URL:** <https://community.graylog.org/t/using-graylog-as-a-siem/15751>\
**Category:** Graylog Central (peer support)\
**Tags:** sidecar\
**Created:** [June 2, 2020, 9:11pm UTC](https://community.graylog.org/t/using-graylog-as-a-siem/15751 "2020-06-02T21:11:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![TB122](https://avatars.discourse-cdn.com/v4/letter/t/ecccb3/32.png) [@TB122](https://community.graylog.org/u/TB122)\
**Post date:** [June 2, 2020, 9:11pm UTC](https://community.graylog.org/t/using-graylog-as-a-siem/15751/1 "2020-06-02T21:11:46Z")

</div>

Currently we have a SIEM and then we send the alerts through Graylog SideCar to Graylog. We aren’t happy with the SIEM. I am interested if anybody uses Graylog as their SIEM. If so how do you get pre-canned correlations like you would in a SIEM? Also how does it stay updated. Also I am having a hard time deciding between Wazuh as more of a HIDS or FileBeats. Wazuh can collect event logs and can also do other stuff. FileBeats/NXLog doesn’t seem to be a HIDS. What would the solution be for the client side? Setup Wazuh manager and then use Graylog SideCar to grab the logs? I just see Graylog pushing themselves as a SIEM more and more. I would like to know how to get there, or how other users have gotten there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [June 16, 2020, 9:11pm UTC](https://community.graylog.org/t/using-graylog-as-a-siem/15751/2 "2020-06-16T21:11:48Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
